Impact
The vulnerability allows an authenticated Email Protection Gateway administrator with limited delegated rights to inject arbitrary content that is written to disk at any writable location accessible to the service account. This permits the attacker to modify application files, alter system configuration, or delete critical files, thereby compromising integrity and potentially causing denial of service. The weakness is a classic instance of absolute path traversal and arbitrary file write.
Affected Systems
Kiteworks Email Protection Gateway is affected. No specific version information is provided, so all installations of the current product family are potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires authenticated access as a delegated administrator, making exploitation plausible in environments where such privileges are granted but not tightly restricted. Successful exploitation can lead to persistence, data tampering, or outage of the gateway service.
OpenCVE Enrichment